Feeds

Sony to offer patch for 'rootkit' DRM

Fix removes cloaking, but not the 'rootkit'

Providing a secure and efficient Helpdesk

Updated Sony BMG said today it will offer a patch for one of its own exploits - one that comes bundled with its music CDs.

The code cloaks itself and by intercepting and redirecting low level windows system calls, forces the audio through a custom player, and restricts the number of CD burns that can be made.

As Sys Internals' Mark Russinovich discovered this week, removing the Sony code using standard anti-malware tools leaves the user with an inoperable CD drive.

Russinovich also pointed out that because the cloaking technique it used to hide itself was so crude, malware authors could hide their own nefarious programs on users hard disks using Sony's DRM software.

However, the patch that Sony will offer doesn't remove the 'rootkit' DRM: it only makes the hidden files visible.

Macintosh and Linux users are unaffected by the DRM kit, which only works on Windows PCs.

It isn't quite the "bombs" the RIAA once suggested it was developing to deter music downloads, but it's in the same spirit.

And here's the patch from First 4 Internet Ltd, the British company that developed the DRM software .

"This Service Pack removes the cloaking technology component that has been recently discussed in a number of articles published regarding the XCP Technology used on SONY BMG content protected CDs." [our emphasis]

The note continues: "This component is not malicious and does not compromise security. However to alleviate any concerns that users may have about the program posing potential security vulnerabilities, this update has been released to enable users to remove this component from their computers."

But wait! Don't do that just yet...

Anti-malware company F-Secure discusses the Sony DRM software here. F-Secure says its rootkit detection software will spot the hidden files, but strongly advises users not to remove it using its Blacklight software, and instead advises users to contact Sony.

"If you find this rootkit from your system, we recommend you don't remove it with our products. As this DRM system is implemented as a filter driver for the CD drive, just blindly removing it might result in an inaccessible CD drive letter," advises F-Secure.

It is alarming how little outrage there is from ordinary PC users. While Register readers are well versed in the restrictions of DRM and the dangers of malware, there's little sign the public shares this knowledge.

Incredibly, the Sony DRM malware has been out on the market for eight months and is bundled on 20 CD titles. Sony said it hadn't received a single complaint until this week. So, disturbingly, most people either haven't run into serious problems yet, or even more disturbingly, don't find the Sony DRM particularly onerous. We pray it's not the latter.

However, Sony's decision to offer a 'patch' that fails to remove the DRM code suggests it isn't too concerned by the howls of outrage heard this week from sophisticated PC users.

And with this level of apathy, the music giants will be emboldened to try these techniques again. And again. And again. ®

Choosing a cloud hosting partner with confidence

More from The Register

next story
SMASH the Bash bug! Apple and Red Hat scramble for patch batches
'Applying multiple security updates is extremely difficult'
Shellshock: 'Larger scale attack' on its way, warn securo-bods
Not just web servers under threat - though TENS of THOUSANDS have been hit
Apple's new iPhone 6 vulnerable to last year's TouchID fingerprint hack
But unsophisticated thieves need not attempt this trick
Oracle SHELLSHOCKER - data titan lists unpatchables
Database kingpin lists 32 products that can't be patched (yet) as GNU fixes second vuln
Who.is does the Harlem Shake
Blame it on LOLing XSS terroristas
Researchers tell black hats: 'YOU'RE SOOO PREDICTABLE'
Want to register that domain? We're way ahead of you.
Stunned by Shellshock Bash bug? Patch all you can – or be punished
UK data watchdog rolls up its sleeves, polishes truncheon
prev story

Whitepapers

A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.